RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

The General Data Protection Regulation, what it actually requires

Regulation (EU) 2016/679 applies directly, while Croatian Act NN 42/2018 supplements it and names AZOP as the supervisory authority. The obligations are set out here with article numbers.

What the GDPR requires

The GDPR applies directly, and the Croatian Act supplements it only where it expressly allows.

The General Data Protection Regulation, Regulation (EU) 2016/679, has applied since 25 May 2018 and does not need transposing into national law. On the same day the Croatian Act implementing it, NN 42/2018, entered into force; it settles what the GDPR left to the member states and, in Article 4, names the Personal Data Protection Agency as the supervisory authority.

The GDPR does not prescribe a list of documents but a set of obligations from which documents follow. Every processing operation needs a legal basis under Article 6, and processing of special categories of data, health data among them, is in principle prohibited and permitted only under the exceptions of Article 9. The principles of Article 5 apply throughout: purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.

The records follow from that. The record of processing activities under Article 30 lists the operations, purposes, categories of data and data subjects, recipients, retention periods and security measures. The information notice under Article 13 tells the data subject what is being done with their data. The contract with a processor under Article 28 binds any supplier processing data on your behalf.

Security of processing is governed by Article 32: technical and organisational measures appropriate to the risk, with pseudonymisation, encryption, system resilience and regular testing named expressly. Where processing is likely to carry a high risk, a data protection impact assessment is carried out beforehand under Article 35.

The data subject rights of Articles 15 to 21 are what most often gets triggered in practice: access, rectification, erasure, restriction of processing, portability and objection. Alongside them runs the duty to appoint a data protection officer under Article 37, which always binds public authorities.

Who is bound, and by what

The obligation depends not on the size of the organisation but on the role and the kind of data.

WHOWHAT BINDS THEMLEGAL BASIS
ControllerDecides on the purposes and means of processing and answers for the principles of Article 5, including demonstrating complianceGDPR, Art. 5
ProcessorProcesses only on the controller instructions and only under a contract with the prescribed contentGDPR, Art. 28
Public authorities and public bodiesMust appoint a data protection officer, whatever the scale of processing; courts acting in their judicial capacity are the exceptionGDPR, Art. 37(1)(a)
Anyone whose core activity is large-scale processing of special categoriesA data protection officer is mandatory, and as a rule an impact assessment before processing startsGDPR, Art. 37(1)(c) and Art. 35
Anyone processing health dataProcessing is in principle prohibited and permitted only under the exceptions, for the purposes of healthcare for exampleGDPR, Art. 9

The Croatian implementing Act supplements the GDPR where it is allowed to. The age of consent for information society services is sixteen, under Article 19. Processing of biometric data is separately regulated, in Articles 21 to 24. Video surveillance footage is kept for no more than six months, unless another statute sets a longer period or it is evidence in proceedings, under Article 29.

The deadlines in one place

Deadlines towards a data subject run from receipt of the request, breach deadlines from becoming aware.

OBLIGATIONDEADLINELEGAL BASIS
Answering a data subject requestOne month from receiptGDPR, Art. 12(3)
Extension for complex or numerous requestsA further two months, with notice to the data subject within the firstGDPR, Art. 12(3)
First copy of the personal dataFree of charge; a reasonable fee may be charged for further copiesGDPR, Art. 15(3)
Notifying a breach to the supervisory authorityWithout undue delay, no later than 72 hours from becoming awareGDPR, Art. 33
Informing data subjects of a high-risk breachWithout undue delayGDPR, Art. 34
Informing a complainant of progress or outcomeThree months, after which a judicial remedy is availableGDPR, Art. 78(2)

The GDPR speaks of one month, not thirty days, so the deadline runs as a calendar month from receipt. Where a breach is notified after 72 hours, the delay must be explained. A breach unlikely to result in a risk to the rights and freedoms of individuals is not notified, but it is entered in the internal breach register.

Fines

Two ranges, and within each the higher of the two amounts applies.

WHAT IS PENALISEDRANGELEGAL BASIS
Breaches of controller and processor obligations, among them security of processing, impact assessment and the officer appointmentUp to 10 million euros or 2 per cent of total worldwide annual turnover, whichever is higherGDPR, Art. 83(4)
Breaches of the processing principles and the conditions for consentUp to 20 million euros or 4 per cent of total worldwide annual turnover, whichever is higherGDPR, Art. 83(5)
Breaches of data subject rights under Articles 12 to 22Up to 20 million euros or 4 per cent, whichever is higherGDPR, Art. 83(5)
Transfers to third countries contrary to Articles 44 to 49Up to 20 million euros or 4 per cent, whichever is higherGDPR, Art. 83(5)
Failure to comply with an order of the supervisory authorityUp to 20 million euros or 4 per cent, whichever is higherGDPR, Art. 83(5)

Croatia has two particularities. No administrative fine may be imposed on a public authority, which under Article 3(2) of the implementing Act means state administration bodies, other state bodies and local and regional self-government units, by virtue of Article 47. The other powers of the supervisory authority are untouched. Public institutions such as hospitals do not fall within that definition and may be fined, but the fine must not endanger the performance of the public service, under Article 44(2). In setting the amount, the nature, gravity and duration of the breach, intent or negligence, the measures taken and cooperation with the authority are all weighed.

Who supervises, and how a case starts

The supervisory authority in Croatia is the Personal Data Protection Agency, seated in Zagreb.

The Agency is an independent state body answerable to the Croatian Parliament. Its powers come from Article 58 of the GDPR and from the implementing Act: it carries out announced and unannounced inspections, takes copies and where necessary temporarily seizes equipment, issues warnings and reprimands, orders compliance, temporarily or permanently bans processing, and imposes administrative fines.

A case most often starts with a complaint from a data subject under Article 77 of the GDPR. In addition, Article 34 of the implementing Act provides for a request to establish an infringement of rights, on which the Agency decides by formal decision; there is no appeal, but the decision may be challenged in an administrative court. If the Agency does not inform the complainant of progress or outcome within three months, a judicial remedy is available under Article 78(2).

The Agency acts free of charge for data subjects, data protection officers, journalists and public authorities. For manifestly unfounded or excessive requests it may charge a reasonable fee or refuse to act, and it charges for opinions that businesses request for their own activity, under Article 43 of the implementing Act.

A personal data breach is notified to the Agency within 72 hours. Where the same event is also a significant cyber incident, the deadlines towards the competent CSIRT under the Cyber Security Act run in parallel: an early warning within 24 hours and a notification within 72 hours. These are two procedures and neither replaces the other, so fines under both may end up being added together.

Frequently asked questions

Questions about the GDPR itself, not already answered above.

Does the GDPR apply to small companies too?

It does. Application does not depend on headcount but on whether you process personal data. The type and scale of processing affect only the extent of particular obligations, such as whether an impact assessment or a data protection officer is required.

Do we need consent for every processing operation?

You do not. Consent is only one of the legal bases in Article 6. Alongside it stand performance of a contract, a legal obligation, vital interests, the public interest and legitimate interests. For health data, processing most often rests on the exceptions in Article 9 rather than on consent.

When is a data protection officer mandatory?

Always for public authorities and public bodies, save for courts acting in their judicial capacity. For others, where the core activity is regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data, under Article 37. The role must be independent and must not decide on the purposes of processing, under Articles 38 and 39.

May a data subject request be refused?

Only if it is manifestly unfounded or excessive, in particular because of its repetitive character, under Article 12(5). The burden of proof lies with the controller. The data subject does not have to give a reason for the request, as the Court of Justice confirmed in case C-307/22.

Is a data subject entitled to learn who looked at their file?

They are entitled to learn the dates and purposes of access, because those too are their personal data. Under the Court of Justice ruling in Pankki S, the names of individual employees are as a rule not covered by that right, unless they are essential for the data subject to exercise their rights effectively. Instead of names, the organisational unit and function are given.

May data be transferred outside the European Union?

It may, but only under the conditions of Articles 44 to 49, an adequacy decision or appropriate safeguards for example. A transfer contrary to those rules falls in the higher fine range of Article 83(5).

Is every personal data breach notified?

Not every one. What goes to the supervisory authority is a breach likely to result in a risk to the rights and freedoms of individuals, under Article 33. Data subjects are told only where the risk is high, under Article 34. But every breach, including one that is not notified, has to be entered in the internal register, with the reasons for not notifying it.

How we can help

This page is about the law. These are the three pieces of work that most often follow from it.

Let us check which provisions actually reach you.

Half an hour, no obligation. We go through what data you process, on what basis, and which of it calls for a record.

Book a callINFO@RISKORIA.EU · +385 97 737 1345